AWS Penetration Testing
Audited by Socket on Jul 28, 2026
2 alerts found:
SecurityMalwareHigh-risk offensive security skill. Its capabilities mostly match its stated pentest purpose, and several tool sources are legitimate, but it enables credential theft, privilege escalation, data extraction, persistence, and defense evasion in AWS. Not confirmed malware, but unsafe to grant to an autonomous agent without strong human approval and tight execution limits.
This artifact is a high-misuse training/playbook that includes explicit malicious Lambda privilege-escalation code (AdministratorAccess via IAM policy attachment) and actionable backdooring/persistence instructions (Lambda code update and invocation), along with abuse-ready workflows for secrets/KMS, enumeration, and container tampering. While it is not demonstrated as executable package malware in the provided fragment, its content is strongly indicative of intentional offensive capability and should be treated as a serious security/supply-chain red flag if included in a dependency or distributed software package.